Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday, May 7, 2023

GPG Verify DupeGuru

https://dupeguru.voltaicideas.net/

https://github.com/arsenetar/dupeguru/releases/tag/4.3.1

$ gpg --verify dupeguru_macOS_Qt_4.3.1.zip.siggpg: assuming signed data in 'dupeguru_macOS_Qt_4.3.1.zip'
gpg: Signature made Fri Jul 8 17:29:40 2022 PDT
gpg: using RSA key D276BDB7E11B3DD328935F71C63300DCE48AB2F1
gpg: Can't check signature: No public key

$ gpg --recv-keys D276BDB7E11B3DD328935F71C63300DCE48AB2F1
gpg: keyserver receive failed: Certificate expired

$ gpg --list-keys
/Users/example/.gnupg/pubring.kbx
------------------------------
pub rsa4096 2017-01-03 [SC]
BF5A669F2272CF4324C1FDA8CFB4C2166397D0D2
uid [ unknown] KeePassXC Release <release@keepassxc.org>

$ gpg --keyserver keyserver.ubuntu.com --recv-keys D276BDB7E11B3DD328935F71C63300DCE48AB2F1
gpg: key C63300DCE48AB2F1: public key "Andrew Senetar <arsenetar@gmail.com>" imported
gpg: Total number processed: 1
gpg: imported: 1

$ gpg --verify dupeguru_macOS_Qt_4.3.1.zip.sig
gpg: assuming signed data in 'dupeguru_macOS_Qt_4.3.1.zip'
gpg: Signature made Fri Jul 8 17:29:40 2022 PDT
gpg: using RSA key D276BDB7E11B3DD328935F71C63300DCE48AB2F1
gpg: Good signature from "Andrew Senetar <arsenetar@gmail.com>" [expired]
gpg: Note: This key has expired!
Primary key fingerprint: D276 BDB7 E11B 3DD3 2893 5F71 C633 00DC E48A B2F1

On Windows:

C:\Temp>gpg --verify dupeguru-win64_4.3.1.zip.sig
gpg: assuming signed data in 'dupeguru-win64_4.3.1.zip'
gpg: Signature made 7/7/2022 8:22:03 PM Pacific Daylight Time
gpg: using RSA key D276BDB7E11B3DD328935F71C63300DCE48AB2F1
gpg: Can't check signature: No public key

C:\Temp>gpg --import D276BDB7E11B3DD328935F71C63300DCE48AB2F1.asc
gpg: key C63300DCE48AB2F1: public key "Andrew Senetar <arsenetar@gmail.com>" imported
gpg: Total number processed: 1
gpg: imported: 1

C:\Temp>gpg --list-keys
C:/Users/Test/AppData/Roaming/gnupg/pubring.kbx
------------------------------------------------
pub rsa4096 2010-10-11 [SC]
C2839ECAD9408FBE9531C3E9F434A1EFAFEEAEA3
uid [ unknown] LibreOffice Build Team (CODE SIGNING KEY) <build@documentfoundation.org>
sub rsa4096 2010-10-11 [E]

pub rsa4096 2019-03-21 [SC] [expired: 2025-12-18]
D276BDB7E11B3DD328935F71C63300DCE48AB2F1
uid [ expired] Andrew Senetar <arsenetar@gmail.com>

C:\Temp\dupguru>gpg --verify dupeguru-win64_4.3.1.zip.sig
gpg: assuming signed data in 'dupeguru-win64_4.3.1.zip'
gpg: Signature made 7/7/2022 8:22:03 PM Pacific Daylight Time
gpg: using RSA key D276BDB7E11B3DD328935F71C63300DCE48AB2F1
gpg: Good signature from "Andrew Senetar <arsenetar@gmail.com>" [expired]
gpg: Note: This key has expired!
Primary key fingerprint: D276 BDB7 E11B 3DD3 2893 5F71 C633 00DC E48A B2F1



Friday, April 28, 2023

Git commands

C:\test>git add .

C:\test>git commit -m 2023-04-28
[master 35ffdfa] 2023-04-28
1 file changed, 3 insertions(+)

C:\test>git push -u origin --all
Enumerating objects: 7, done.
Counting objects: 100% (7/7), done.
Delta compression using up to 4 threads
Compressing objects: 100% (4/4), done.
Writing objects: 100% (4/4), 530 bytes | 88.00 KiB/s, done.
Total 4 (delta 3), reused 0 (delta 0), pack-reused 0
remote: Resolving deltas: 100% (3/3), completed with 3 local objects.
To https://github.com/testxxxxx/testxxxxx.github.io.git
bb422c3..35ffdfa master -> master
branch 'master' set up to track 'origin/master'.

Thursday, March 30, 2023

KeePassXC 2.5.2 released - KeePassXC

https://keepassxc.org/blog/2020-01-04-2.5.2-released/
https://keepassxc.org/download/
https://keepassxc.org/verifying-signatures/

https://keepassxc.org/verifying-signatures/

"C:\Program Files\Git\usr\bin\gpg" --verify KeePassXC-*-Win64.msi.sig
gpg: assuming signed data in 'KeePassXC-2.5.2-Win64.msi'
gpg: Signature made Sat Jan 4 06:20:56 2020 PST
gpg: using RSA key C1E4CBA3AD78D3AFD894F9E0B7A66F03B59076A8
gpg: Can't check signature: No public key

"C:\Program Files\Git\usr\bin\gpg" --verify KeePassXC-*-Win32.msi.sig
gpg: assuming signed data in 'KeePassXC-2.5.2-Win32.msi'
gpg: Signature made Sat Jan 4 06:38:57 2020 PST
gpg: using RSA key C1E4CBA3AD78D3AFD894F9E0B7A66F03B59076A8
gpg: Can't check signature: No public key

"C:\Program Files\Git\usr\bin\gpg" --verify KeePassXC-*.dmg.sig
gpg: assuming signed data in 'KeePassXC-2.5.2.dmg'
gpg: Signature made Sat Jan 4 07:11:27 2020 PST
gpg: using RSA key C1E4CBA3AD78D3AFD894F9E0B7A66F03B59076A8
gpg: Can't check signature: No public key

From DIGEST files:
9755d3f16b98db6f8d25e02a445a0b7f4aae822e514105cec02df4c25b53f993 KeePassXC-2.5.2.dmg
0a97a99eaa83274acb524978d32bfddae5e1500c151a2393318051e4e8bc952f *KeePassXC-2.5.2-Win32.msi
3380d96543795f56ed258ebb82e4a802887ead6820e314eb7263dc41cdcf2099 *KeePassXC-2.5.2-Win64.msi
CertUtil -hashfile KeePassXC-2.5.2.dmg sha256
SHA256 hash of KeePassXC-2.5.2.dmg:
9755d3f16b98db6f8d25e02a445a0b7f4aae822e514105cec02df4c25b53f993
CertUtil: -hashfile command completed successfully.
CertUtil -hashfile KeePassXC-2.5.2-win32.msi sha256
SHA256 hash of KeePassXC-2.5.2-win32.msi:
0a97a99eaa83274acb524978d32bfddae5e1500c151a2393318051e4e8bc952f
CertUtil: -hashfile command completed successfully.
CertUtil -hashfile KeePassXC-2.5.2-Win64.msi sha256
SHA256 hash of KeePassXC-2.5.2-Win64.msi:
3380d96543795f56ed258ebb82e4a802887ead6820e314eb7263dc41cdcf2099
CertUtil: -hashfile command completed successfully.
CertUtil -hashfile KeePassXC-2.5.2-Sierra.dmg sha256
SHA256 hash of KeePassXC-2.5.2-Sierra.dmg:
2fa99590e8390fa6333b861a48280d2dd736238c40f70ba2aa30ac32d849a669
CertUtil: -hashfile command completed successfully.

Tuesday, December 6, 2022

How to Verify the Integrity of the Downloaded Keka the macOS file archiver

Go to https://www.keka.io/en/

Download v1.2.58
36.4 MB | Requires Mac OS X 10.10 or newer
Changelog | Legacy | Helper | iOS
MD5: 316c2614330f6a9bf8776eb312c6d54f

$ openssl dgst -md5 Keka-1.2.58.dmg
MD5(Keka-1.2.58.dmg)= 316c2614330f6a9bf8776eb312c6d54f

Is the hash match?

Source code https://github.com/aonez/Keka

Sunday, October 3, 2021

Validate integrity of LibreOffice downloaded files on Mac

On this page https://www.libreoffice.org/download/download/, click info
https://download.documentfoundation.org/libreoffice/stable/7.2.1/mac/x86_64/LibreOffice_7.2.1_MacOS_x86-64.dmg.mirrorlist

Mirrors for LibreOffice_7.2.1_MacOS_x86-64.dmg
File information

Filename: LibreOffice_7.2.1_MacOS_x86-64.dmg
Path: /libreoffice/stable/7.2.1/mac/x86_64/LibreOffice_7.2.1_MacOS_x86-64.dmg
Size: 267M (279867887 bytes)
Last modified: Fri, 10 Sep 2021 09:43:36 GMT (Unix time: 1631267016)
SHA-256 Hash: b83e841360fa6ee9e42bfc1579ce9ae135972d6e7a01e79d1b975c2b855ff152
SHA-1 Hash: ad46a513f7c2047f632d8a3929a23b74aaebcc3d
MD5 Hash: 741cd9f35e133d0b2cc1944dc362cb0f
BitTorrent Information Hash: bcb717c49259229b9108c0967679dc2f53c9aba9
PGP signature available

At the terminal:
$ openssl dgst -sha256 LibreOffice_7.2.1_MacOS_x86-64.dmg
SHA256(LibreOffice_7.2.1_MacOS_x86-64.dmg)= b83e841360fa6ee9e42bfc1579ce9ae135972d6e7a01e79d1b975c2b855ff152

Search and compare the hash sum for matching before install

Tuesday, January 1, 2013

New Year New Password

Your password should change frequently. If you cannot change every month, every quarter, then at least once a year.

When you change the password, it should NOT in "The 25 worst passwords of 2012". You should NOT using the same password for all accounts. Use the KeePass or a password protected LibreOffice document to keep track your password. Read "The guide to password security (and why you should care)" for more info.

Happy New Year!

Saturday, December 22, 2012

Beware of Fake Federal Express Emails

When I maintained my client's computer few days ago, I found his computer infected by trojan downloader Win32/Kuluoz.B


These trojans infected my client's computer since he clicked on the fake email claimed from Federal Express.


As a matter of fact, the delivery companies like Federal Express, UPS, DHL and US Post Office never send email notification. They don't know your email. If they cannot delivery package, they will left a note at your door.

It took me an hour to clean up and re-scan whole computer to make sure it clean. So, beware when you check email.

How to Install Keka on macOS

Download latest version from https://www.keka.io/en/ Copy the MD5 hash value from Keka website to compare later (MD5: 8729f9d08d10293fa1ee65...